|
Plagegeister aller Art und deren Bekämpfung: Computer piepst dauernd, VirenmeldungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
10.02.2014, 09:38 | #16 |
| Computer piepst dauernd, Virenmeldung Alles klar, danke. Wahnsinn, was du für eine Geduld mit den Leuten hast. Das wird nach der Bereinigung mit einem kleinen Geldbetrag honoriert. Hier der Bericht von ESET. Scan hat sehr lange gedauert. Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=d40b86f54ccb1140a46fa89220ae3987 # engine=17000 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-10 04:28:11 # local_time=2014-02-10 05:28:11 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 94 116827 13763114 109595 0 # compatibility_mode=5893 16776574 100 94 18472406 143636341 0 0 # scanned=322765 # found=0 # cleaned=0 # scan_time=66645 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Flash Player 12.0.0.43 Flash Player out of Date! Adobe Reader 10.1.9 Adobe Reader out of Date! Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-02-2014 03 Ran by Anerose (administrator) on ANDI on 10-02-2014 09:37:08 Running from C:\Users\Anerose\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Users\Anerose\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Oracle Corporation) C:\app\Anerose\product\11.2.0\dbhome_1\bin\nmesrvc.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Oracle Corporation) C:\app\Anerose\product\11.2.0\dbhome_1\BIN\TNSLSNR.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Oracle Corporation) c:\app\anerose\product\11.2.0\dbhome_1\bin\ORACLE.EXE (Microsoft Corporation) C:\Windows\system32\cmd.exe () C:\app\Anerose\product\11.2.0\dbhome_1\perl\bin\perl.exe (Microsoft Corporation) C:\Windows\system32\cmd.exe (Sun Microsystems, Inc.) C:\app\Anerose\product\11.2.0\dbhome_1\jdk\bin\java.exe (Oracle Corporation) C:\app\Anerose\product\11.2.0\dbhome_1\bin\emagent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Oracle Corporation) C:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IntelliPoint] - C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation) HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-748884160-2445454426-2993544468-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-748884160-2445454426-2993544468-1000\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Anerose\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () Startup: C:\Users\Anerose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=hp&fr=linkury-tb&installDate=09/02/2014&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3CE6C74887B3CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000 SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File DPF: HKLM {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Anerose\AppData\Roaming\Mozilla\Firefox\Profiles\0zhm3czg.default-1380816757915 FF NewTab: about:blank FF DefaultSearchEngine: Google FF SelectedSearchEngine: Google FF Homepage: about:home FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=3ba83619-1b0f-e8a0-7830-47c545c2ab95&searchtype=ds&fr=linkury-tb&installDate={installDate}&type=hp1000&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Anerose\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Anerose\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Anerose\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Anerose\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Anerose\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Anerose\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin ProgramFiles/Appdata: C:\Users\Anerose\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Anerose\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin ProgramFiles/Appdata: C:\Users\Anerose\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Anerose\AppData\Roaming\Mozilla\Firefox\Profiles\0zhm3czg.default-1380816757915\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-03] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-12] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-17] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 OracleDBConsoleorcl; C:\app\Anerose\product\11.2.0\dbhome_1\bin\nmesrvc.exe [35328 2010-03-02] (Oracle Corporation) S4 OracleJobSchedulerORCL; c:\app\anerose\product\11.2.0\dbhome_1\Bin\extjob.exe [45568 2010-03-30] () S4 OracleJobSchedulerXE; c:\oraclexe\app\oracle\product\11.2.0\server\Bin\extjob.exe [49152 2011-08-27] () S3 OracleMTSRecoveryService; C:\oraclexe\app\oracle\product\11.2.0\server\BIN\omtsreco.exe [69632 2011-08-27] (Oracle Corporation) S3 OracleOraDb11g_home1ClrAgent; C:\app\Anerose\product\11.2.0\dbhome_1\bin\OraClrAgnt.exe [83968 2010-03-12] (Oracle Corporation) S3 OracleOraDb11g_home2ClrAgent; C:\app\Anerose\product\11.2.0\dbhome_2\bin\OraClrAgnt.exe [83968 2010-03-12] (Oracle Corporation) R2 OracleServiceORCL; c:\app\anerose\product\11.2.0\dbhome_1\bin\ORACLE.EXE [134018048 2010-03-30] (Oracle Corporation) S2 OracleServiceXE; c:\oraclexe\app\oracle\product\11.2.0\server\bin\ORACLE.EXE [115773440 2011-08-27] (Oracle Corporation) S3 OracleVssWriterORCL; c:\app\anerose\product\11.2.0\dbhome_1\bin\OraVSSW.exe [192000 2010-03-30] () S3 OracleXEClrAgent; C:\oraclexe\app\oracle\product\11.2.0\server\bin\OraClrAgnt.exe [12800 2011-08-27] (Oracle Corporation) R2 OracleXETNSListener; C:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe [512000 2011-08-27] (Oracle Corporation) R2 OracleOraDb11g_home1TNSListener; C:\app\Anerose\product\11.2.0\dbhome_1\BIN\TNSLSNR [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-01] (Avira Operations GmbH & Co. KG) R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (EZB Systems, Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-08-05] () S3 TrojanKillerDriver; C:\Windows\System32\DRIVERS\gtkdrv.sys [16640 2013-06-26] (Windows (R) Win 7 DDK provider) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-10 09:33 - 2014-02-10 09:33 - 00987425 _____ () C:\Users\Anerose\Desktop\SecurityCheck.exe 2014-02-09 11:10 - 2014-02-09 11:10 - 00001160 _____ () C:\Users\Anerose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-02-09 11:03 - 2014-02-09 11:03 - 00000000 ____D () C:\Users\Anerose\AppData\Roaming\OpenCandy 2014-02-09 11:02 - 2014-02-09 11:02 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Anerose\Documents\FreeYouTubeToMP3Converter-3.12.20.1230.exe 2014-02-09 10:54 - 2014-02-09 10:54 - 02347384 _____ (ESET) C:\Users\Anerose\Desktop\esetsmartinstaller_enu.exe 2014-02-09 10:54 - 2014-02-09 10:54 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-08 18:55 - 2014-02-10 09:36 - 00000000 ____D () C:\Users\Anerose\Desktop\FRST-OlderVersion 2014-02-08 18:54 - 2014-02-08 18:54 - 00000775 _____ () C:\Users\Anerose\Desktop\JRT.txt 2014-02-08 17:56 - 2014-02-08 17:56 - 01166132 _____ () C:\Users\Anerose\Desktop\adwcleaner.exe 2014-02-07 15:10 - 2014-02-09 11:04 - 00000000 ____D () C:\Users\Anerose\Documents\USBMp3 2014-02-07 10:29 - 2014-02-07 10:29 - 00132922 _____ () C:\ComboFix.txt 2014-02-07 10:01 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-07 10:01 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-07 10:01 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-07 10:01 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-07 10:01 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-07 10:01 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-07 10:01 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-07 10:01 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-07 09:57 - 2014-02-07 10:29 - 00000000 ____D () C:\Qoobox 2014-02-07 09:56 - 2014-02-07 09:56 - 05180173 ____R (Swearware) C:\Users\Anerose\Desktop\ComboFix.exe 2014-02-06 21:05 - 2014-02-06 21:05 - 00722409 _____ () C:\Users\Anerose\Documents\L_Clan_SKYFALL=vs=Zuppi 05feb.zip 2014-02-06 21:05 - 2014-02-06 21:04 - 00713375 _____ () C:\Users\Anerose\Documents\Zuppi=vs=L_Clan_SKYFALL 05feb.zip 2014-02-06 14:17 - 2014-02-06 14:17 - 04101441 _____ () C:\Users\Anerose\Desktop\tdsskiller.zip 2014-02-05 17:57 - 2014-02-05 17:57 - 00208216 _____ (Kaspersky Lab, GERT) C:\Windows\system32\Drivers\69609454.sys 2014-02-05 17:55 - 2013-11-18 06:28 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Anerose\Desktop\TDSSKiller.exe 2014-02-04 19:56 - 2014-02-08 18:57 - 00010923 _____ () C:\Users\Anerose\Desktop\Addition.txt 2014-02-04 19:54 - 2014-02-10 09:37 - 00016010 _____ () C:\Users\Anerose\Desktop\FRST.txt 2014-02-04 19:54 - 2014-02-10 09:37 - 00000000 ____D () C:\FRST 2014-02-04 19:54 - 2014-02-10 09:36 - 02170880 _____ (Farbar) C:\Users\Anerose\Desktop\FRST64.exe 2014-02-04 15:48 - 2014-02-04 15:48 - 00000000 ____D () C:\Program Files\ffdshow 2014-02-04 15:48 - 2013-01-06 22:24 - 00127488 _____ () C:\Windows\system32\ff_vfw.dll 2014-02-04 15:41 - 2014-02-04 15:41 - 09498233 _____ () C:\Users\Anerose\Documents\ffdshow13.zip 2014-02-04 15:35 - 2014-02-04 15:34 - 01251941 _____ () C:\Users\Anerose\Documents\AUDIO_20140204_150439.3gp 2014-02-03 21:58 - 2014-02-03 21:58 - 00012384 _____ () C:\Users\Anerose\Documents\DBIS.odt 2014-02-02 11:23 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-02-02 11:23 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-02-02 11:23 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-02-02 11:23 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-02-02 11:22 - 2014-02-02 11:23 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-02 11:21 - 2014-02-02 11:21 - 00921000 _____ (Oracle Corporation) C:\Users\Anerose\Documents\jxpiinstall.exe 2014-01-28 17:12 - 2014-01-28 17:12 - 06248156 _____ () C:\Users\Anerose\Documents\ADS2.zip 2014-01-24 15:53 - 2014-01-24 15:54 - 00374427 _____ () C:\Users\Anerose\Documents\Klausur2.zip 2014-01-23 18:04 - 2014-01-23 18:05 - 00373822 _____ () C:\Users\Anerose\Documents\Klausur.rar 2014-01-21 22:03 - 2014-01-21 22:08 - 259117681 _____ () C:\Users\Anerose\Documents\deadpoetsmixtape2.zip 2014-01-15 06:48 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 06:48 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 06:48 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 06:48 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 06:48 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 06:48 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 06:48 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 06:48 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-12 20:15 - 2014-01-12 20:15 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-12 19:05 - 2014-01-12 19:05 - 00002096 _____ () C:\Users\Public\Desktop\Get Started With Oracle Database 11g Express Edition .lnk 2014-01-12 19:04 - 2014-01-12 19:04 - 00000000 ____D () C:\oraclexe ==================== One Month Modified Files and Folders ======= 2014-02-10 09:37 - 2014-02-04 19:54 - 00016010 _____ () C:\Users\Anerose\Desktop\FRST.txt 2014-02-10 09:37 - 2014-02-04 19:54 - 00000000 ____D () C:\FRST 2014-02-10 09:36 - 2014-02-08 18:55 - 00000000 ____D () C:\Users\Anerose\Desktop\FRST-OlderVersion 2014-02-10 09:36 - 2014-02-04 19:54 - 02170880 _____ (Farbar) C:\Users\Anerose\Desktop\FRST64.exe 2014-02-10 09:35 - 2012-07-04 14:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-10 09:33 - 2014-02-10 09:33 - 00987425 _____ () C:\Users\Anerose\Desktop\SecurityCheck.exe 2014-02-10 09:01 - 2012-10-27 13:23 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-748884160-2445454426-2993544468-1000UA.job 2014-02-10 09:01 - 2012-10-27 13:23 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-748884160-2445454426-2993544468-1000Core.job 2014-02-10 08:49 - 2012-08-23 05:18 - 00000000 ____D () C:\Users\Anerose\AppData\Roaming\Skype 2014-02-10 05:10 - 2012-07-04 11:28 - 02052269 _____ () C:\Windows\WindowsUpdate.log 2014-02-10 02:02 - 2012-07-05 14:23 - 00000000 ____D () C:\Users\Anerose\AppData\Roaming\Mozilla 2014-02-09 11:10 - 2014-02-09 11:10 - 00001160 _____ () C:\Users\Anerose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-02-09 11:08 - 2013-03-07 19:04 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-02-09 11:08 - 2012-07-13 09:10 - 00000000 ____D () C:\Users\Anerose\AppData\Roaming\DVDVideoSoft 2014-02-09 11:04 - 2014-02-07 15:10 - 00000000 ____D () C:\Users\Anerose\Documents\USBMp3 2014-02-09 11:03 - 2014-02-09 11:03 - 00000000 ____D () C:\Users\Anerose\AppData\Roaming\OpenCandy 2014-02-09 11:02 - 2014-02-09 11:02 - 34008992 _____ (DVDVideoSoft Ltd. ) C:\Users\Anerose\Documents\FreeYouTubeToMP3Converter-3.12.20.1230.exe 2014-02-09 11:02 - 2009-07-14 05:45 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-09 11:02 - 2009-07-14 05:45 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-09 10:54 - 2014-02-09 10:54 - 02347384 _____ (ESET) C:\Users\Anerose\Desktop\esetsmartinstaller_enu.exe 2014-02-09 10:54 - 2014-02-09 10:54 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-09 10:49 - 2013-01-09 17:53 - 00041528 _____ () C:\Windows\setupact.log 2014-02-09 10:49 - 2012-11-02 17:09 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-09 10:49 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-08 18:57 - 2014-02-04 19:56 - 00010923 _____ () C:\Users\Anerose\Desktop\Addition.txt 2014-02-08 18:54 - 2014-02-08 18:54 - 00000775 _____ () C:\Users\Anerose\Desktop\JRT.txt 2014-02-08 18:42 - 2013-09-01 15:17 - 00000000 ____D () C:\AdwCleaner 2014-02-08 18:42 - 2012-07-04 11:33 - 00000999 _____ () C:\Users\Anerose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-08 17:58 - 2013-03-08 09:45 - 00242820 _____ () C:\Windows\PFRO.log 2014-02-08 17:56 - 2014-02-08 17:56 - 01166132 _____ () C:\Users\Anerose\Desktop\adwcleaner.exe 2014-02-07 10:29 - 2014-02-07 10:29 - 00132922 _____ () C:\ComboFix.txt 2014-02-07 10:29 - 2014-02-07 09:57 - 00000000 ____D () C:\Qoobox 2014-02-07 10:14 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-07 09:56 - 2014-02-07 09:56 - 05180173 ____R (Swearware) C:\Users\Anerose\Desktop\ComboFix.exe 2014-02-06 21:05 - 2014-02-06 21:05 - 00722409 _____ () C:\Users\Anerose\Documents\L_Clan_SKYFALL=vs=Zuppi 05feb.zip 2014-02-06 21:04 - 2014-02-06 21:05 - 00713375 _____ () C:\Users\Anerose\Documents\Zuppi=vs=L_Clan_SKYFALL 05feb.zip 2014-02-06 14:17 - 2014-02-06 14:17 - 04101441 _____ () C:\Users\Anerose\Desktop\tdsskiller.zip 2014-02-05 19:35 - 2012-07-04 14:24 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-05 19:35 - 2012-07-04 14:24 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-05 19:35 - 2012-07-04 14:24 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-05 17:57 - 2014-02-05 17:57 - 00208216 _____ (Kaspersky Lab, GERT) C:\Windows\system32\Drivers\69609454.sys 2014-02-04 15:48 - 2014-02-04 15:48 - 00000000 ____D () C:\Program Files\ffdshow 2014-02-04 15:41 - 2014-02-04 15:41 - 09498233 _____ () C:\Users\Anerose\Documents\ffdshow13.zip 2014-02-04 15:34 - 2014-02-04 15:35 - 01251941 _____ () C:\Users\Anerose\Documents\AUDIO_20140204_150439.3gp 2014-02-03 21:58 - 2014-02-03 21:58 - 00012384 _____ () C:\Users\Anerose\Documents\DBIS.odt 2014-02-02 11:23 - 2014-02-02 11:22 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-02-02 11:23 - 2013-10-20 10:24 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-02 11:23 - 2013-06-25 17:51 - 00000000 ____D () C:\Program Files (x86)\Java 2014-02-02 11:21 - 2014-02-02 11:21 - 00921000 _____ (Oracle Corporation) C:\Users\Anerose\Documents\jxpiinstall.exe 2014-01-28 17:12 - 2014-01-28 17:12 - 06248156 _____ () C:\Users\Anerose\Documents\ADS2.zip 2014-01-24 15:54 - 2014-01-24 15:53 - 00374427 _____ () C:\Users\Anerose\Documents\Klausur2.zip 2014-01-24 12:00 - 2013-08-07 16:28 - 00000027 _____ () C:\Users\Anerose\Desktop\Liste.txt 2014-01-23 18:05 - 2014-01-23 18:04 - 00373822 _____ () C:\Users\Anerose\Documents\Klausur.rar 2014-01-23 18:04 - 2009-07-14 18:58 - 00702234 _____ () C:\Windows\system32\perfh007.dat 2014-01-23 18:04 - 2009-07-14 18:58 - 00150154 _____ () C:\Windows\system32\perfc007.dat 2014-01-23 18:04 - 2009-07-14 06:13 - 01629002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-01-21 22:08 - 2014-01-21 22:03 - 259117681 _____ () C:\Users\Anerose\Documents\deadpoetsmixtape2.zip 2014-01-19 08:33 - 2012-07-04 11:50 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-01-18 11:10 - 2012-07-05 14:32 - 00000000 ____D () C:\Users\Anerose\AppData\Local\Adobe 2014-01-15 20:35 - 2009-07-14 05:45 - 00330344 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-15 07:32 - 2013-08-18 07:28 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 07:30 - 2012-07-04 12:07 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2014-01-12 20:15 - 2014-01-12 20:15 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2014-01-12 20:15 - 2013-01-09 17:50 - 00000000 ____D () C:\Program Files\Java 2014-01-12 20:12 - 2014-01-03 13:00 - 00000000 ____D () C:\Users\Anerose\Documents\DBIS 2014-01-12 19:43 - 2014-01-03 13:26 - 00000000 ____D () C:\Program Files\Oracle 2014-01-12 19:07 - 2012-07-04 14:15 - 01650996 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-01-12 19:06 - 2012-07-05 17:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-12 19:05 - 2014-01-12 19:05 - 00002096 _____ () C:\Users\Public\Desktop\Get Started With Oracle Database 11g Express Edition .lnk 2014-01-12 19:04 - 2014-01-12 19:04 - 00000000 ____D () C:\oraclexe Some content of TEMP: ==================== C:\Users\Anerose\AppData\Local\Temp\avgnt.exe C:\Users\Anerose\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-10 06:35 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-02-2014 03 Ran by Anerose at 2014-02-10 09:37:39 Running from C:\Users\Anerose\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) - Deutsch (x32 Version: 10.1.9 - Adobe Systems Incorporated) Age of Empires III - The WarChiefs (x32 Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III - The WarChiefs (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Age of Empires III (x32 Version: 1.00.0000 - Microsoft Game Studios) Age of Empires III (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden Amazon MP3-Downloader 1.0.18 (HKCU Version: 1.0.18 - Amazon Services LLC) Audacity 2.0 (x32 Version: - Audacity Team) Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira) Belkin Connect Wireless USB Adapter (x32 Version: 1.0.0.3 - Belkin) Belkin Connect Wireless USB Adapter (x32 Version: 1.0.0.3 - Belkin) Hidden Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32 Version: - ) Hidden Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: - ) Hidden CCleaner (Version: 3.26 - Piriform) CDBurnerXP (x32 Version: 4.4.2.3442 - CDBurnerXP) CodeBlocks (HKCU Version: 10.05 - The Code::Blocks Team) ESET Online Scanner v3 (x32 Version: - ) ffdshow x64 v1.3.4500 [2013-01-06] (Version: 1.3.4500.0 - ) FlashFXP v4.2 (x32 Version: 4.2.5.1813 - OpenSight Software, LLC) Free Audio CD to MP3 Converter version 1.3.12.1228 (x32 Version: 1.3.12.1228 - DVDVideoSoft Ltd.) GameRanger (HKCU Version: - GameRanger Technologies) Google Talk Plugin (x32 Version: 5.1.4.17398 - Google) GPL Ghostscript (Version: 9.07 - Artifex Software Inc.) GSview 5.0 (Version: 5.0 - Ghostgum Software Pty Ltd) Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java SE Development Kit 7 Update 45 (64-bit) (Version: 1.7.0.450 - Oracle) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Maple 15 (32-bit) (x32 Version: 15.0.0.0 - Maplesoft) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Age of Empires (x32 Version: - ) Microsoft Age of Empires Expansion (x32 Version: - ) Microsoft Age of Empires II (x32 Version: - ) Microsoft Age of Empires II: The Conquerors Expansion (x32 Version: - ) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft IntelliPoint 8.2 (Version: 8.20.468.0 - Microsoft Corporation) Microsoft IntelliPoint 8.2 (Version: 8.20.468.0 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) MiKTeX 2.9 (Version: 2.9 - MiKTeX.org) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.06 (Version: 311.06 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.108.688 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden NVIDIA Update 1.11.3 (Version: 1.11.3 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden OpenOffice.org 3.4.1 (x32 Version: 3.41.9593 - Apache Software Foundation) Oracle Database 11g Express Edition (x32 Version: 11.2.0 - Oracle Corporation) Oracle Database 11g Express Edition (x32 Version: 11.2.0 - Oracle Corporation) Hidden Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.) Perspective 1.0 (x32 Version: 1.0 - Widdershins) Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Texmaker (x32 Version: - ) Trojan Killer (x32 Version: 2.1.8.9 - Gridinsoft LLC) UltraISO Premium V9.53 (x32 Version: - ) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation) WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH) Xiph.Org Open Codecs 0.85.17777 (x32 Version: 0.85.17777 - Xiph.Org) XMedia Recode Version 3.1.4.8 (x32 Version: 3.1.4.8 - XMedia Recode) ==================== Restore Points ========================= 05-02-2014 16:54:29 Windows Update 07-02-2014 09:01:11 ComboFix created restore point 09-02-2014 10:01:14 Windows Update 09-02-2014 18:00:52 Windows-Sicherung ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {3EBCE773-BC32-4F9C-AC6E-7C2431F0191F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-748884160-2445454426-2993544468-1000Core => C:\Users\Anerose\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-27] (Google Inc.) Task: {4329659E-9074-4082-B5AB-4E770AD26D8C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-05] (Adobe Systems Incorporated) Task: {6E31C610-A706-4668-8025-7F1C79AB7B11} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {A006888D-90A9-4123-A947-EAC56C0C65F1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-748884160-2445454426-2993544468-1000UA => C:\Users\Anerose\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-27] (Google Inc.) Task: {A4CA8960-B436-45E0-A43E-DFB3C71156A3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-12-19] (Piriform Ltd) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-748884160-2445454426-2993544468-1000Core.job => C:\Users\Anerose\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-748884160-2445454426-2993544468-1000UA.job => C:\Users\Anerose\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-05-22 19:50 - 2013-05-22 19:50 - 00400704 _____ () C:\Users\Anerose\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe 2013-09-03 22:25 - 2013-09-03 22:24 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2012-08-10 15:51 - 2012-08-10 15:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2013-12-20 11:29 - 2013-12-20 11:29 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-02-05 19:35 - 2014-02-05 19:35 - 16287624 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/10/2014 09:32:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/10/2014 06:36:25 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 07:06:46 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung war nicht erfolgreich. Fehler: "Am Sicherungsspeicherort ist nicht genügend freier Speicherplatz verfügbar, um die Daten zu sichern. (0x80780048)" Error: (02/09/2014 10:57:38 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: perl.exe, Version: 0.0.0.0, Zeitstempel: 0x4ae02416 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc0000374 Fehleroffset: 0x00000000000c4102 ID des fehlerhaften Prozesses: 0xe58 Startzeit der fehlerhaften Anwendung: 0xperl.exe0 Pfad der fehlerhaften Anwendung: perl.exe1 Pfad des fehlerhaften Moduls: perl.exe2 Berichtskennung: perl.exe3 Error: (02/09/2014 10:54:54 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 10:54:43 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 10:54:41 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/08/2014 10:51:43 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_12_0_0_44.exe, Version: 12.0.0.44, Zeitstempel: 0x52e70cce Name des fehlerhaften Moduls: FlashPlayerPlugin_12_0_0_44.exe, Version: 12.0.0.44, Zeitstempel: 0x52e70cce Ausnahmecode: 0x40000015 Fehleroffset: 0x00017b60 ID des fehlerhaften Prozesses: 0x9e8 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_12_0_0_44.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_12_0_0_44.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_12_0_0_44.exe2 Berichtskennung: FlashPlayerPlugin_12_0_0_44.exe3 System errors: ============= Error: (02/09/2014 10:54:50 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (02/09/2014 10:54:50 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (02/09/2014 10:50:30 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "OracleServiceXE" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/09/2014 10:50:30 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst OracleServiceXE erreicht. Microsoft Office Sessions: ========================= Error: (02/10/2014 09:32:11 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (02/10/2014 06:36:25 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestc:\program files (x86)\ESET\eset online scanner\ESETSmartInstaller.exe Error: (02/09/2014 07:06:46 PM) (Source: Windows Backup)(User: ) Description: Am Sicherungsspeicherort ist nicht genügend freier Speicherplatz verfügbar, um die Daten zu sichern. (0x80780048) Error: (02/09/2014 10:57:38 AM) (Source: Application Error)(User: ) Description: perl.exe0.0.0.04ae02416ntdll.dll6.1.7601.18247521eaf24c000037400000000000c4102e5801cf257d5a234c0eC:\app\Anerose\product\11.2.0\dbhome_1\perl\bin\perl.exeC:\Windows\SYSTEM32\ntdll.dll9ac86653-9170-11e3-ac55-6cf0490be230 Error: (02/09/2014 10:54:54 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Anerose\Desktop\esetsmartinstaller_enu.exe Error: (02/09/2014 10:54:43 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Anerose\Desktop\esetsmartinstaller_enu.exe Error: (02/09/2014 10:54:41 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Anerose\Desktop\esetsmartinstaller_enu.exe Error: (02/08/2014 10:51:43 PM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_12_0_0_44.exe12.0.0.4452e70cceFlashPlayerPlugin_12_0_0_44.exe12.0.0.4452e70cce4000001500017b609e801cf24f75d9183b6C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe328a75d3-910b-11e3-bbd2-6cf0490be230 ==================== Memory info =========================== Percentage of memory in use: 75% Total physical RAM: 4093.09 MB Available physical RAM: 997.31 MB Total Pagefile: 8184.37 MB Available Pagefile: 3799.23 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:292.87 GB) (Free:203.81 GB) NTFS Drive d: (DATA) (Fixed) (Total:638.54 GB) (Free:1.76 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 95165474) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=639 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
11.02.2014, 08:29 | #17 |
/// the machine /// TB-Ausbilder | Computer piepst dauernd, Virenmeldung Fertig
__________________Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
12.02.2014, 10:42 | #18 |
| Computer piepst dauernd, Virenmeldung Erledigt. Kannst den Thread aus deinen Abos löschen. Noch mal vielen herzlichen Dank!
__________________ |
13.02.2014, 05:52 | #19 |
/// the machine /// TB-Ausbilder | Computer piepst dauernd, Virenmeldung Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Computer piepst dauernd, Virenmeldung |
abbrechen, avira, bitte um hilfe, compu, computer, dankbar, dauernd, fertig, fund, heute, hilfe, lange, mbam, meldung, pieps, piepst, player, problem, scan, scann, scanne, scannen, scannt, sekunden, virenmeldung |